# IP INTELLIGENCE BRIEFING: 39.34.186.31
Classification: LOW RISK
Date of Analysis: 2026-07-25
Status: Active Monitoring
---
## EXECUTIVE SUMMARY
IP address 39.34.186.31/32 is associated with Pakistan Telecommunication Company Limited (PTCL) broadband infrastructure. The IP presents low-risk characteristics with a current risk score of 25. No active threat indicators, malware campaigns, or malicious activities have been observed. The address is currently in a firewalled state with no services running.
---
## OWNERSHIP AND REGISTRATION
- ASN: 132165
- Organization: Munir Ahmed / PTCLBB-PK
- Netname: PTCLBB-PK
- RIR: APNIC (Asia Pacific)
- CIDR Block: 39.32.0.0/11
- Abuse Contact: Available via RDAP
---
## GEOLOCATION DATA
- Reported Country: Pakistan (PK) / France (FR) - Data inconsistency detected
- Geographic Consensus: False (multiple conflicting sources)
- Plausibility Score: High
- Minimum Possible RTT: 112.8ms
- Distance from Origin: 5,641.5km
*Note: Geographic validation shows ICMP blocking preventing full validation. Ownership data clearly indicates Pakistan Telecom infrastructure.*
---
## THREAT ASSESSMENT
Current Risk Profile
- Risk Score: 25 (Low Risk)
- Abuse Confidence: Not scored
- Blacklist Status: 0 out of 8 DNSBL lists (1 listing noted in control plane data)
- Threat Indicators: None detected
Attack Surface
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None identified
Network Classification
- Infrastructure Type: Residential/Broadband
- Cloud Provider: No
- CDN: No
- VPN Service: No
- Proxy Service: No
- Hosting: No
---
## NETWORK STATE
- Service Status: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: Not applicable
- HTTP Title: Not applicable
- Service Purpose: Firewalled / No Services
---
## NEIGHBORHOOD ANALYSIS (39.34.186.0/24)
- Abuse Density: Clean (0.0)
- Classification: Clean
- Total Subnet IPs: 5 active
- Threat IPs: 0
Sibling IP Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 39.34.186.6 | 25 | 50 |
| 39.34.186.79 | 25 | 50 |
| 39.34.186.194 | 0 | 50 |
| 39.34.186.217 | 0 | 50 |
---
## OBSERVATION HISTORY
Signal Timeline (14 observations)
- Most Recent: 2026-07-25T14:07:34
- Threat Observation Count: 0
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: False
Key Historical Signals:
- Geolocation: Confirmed Pakistan (PK) coordinates in multiple observations
- DNSSEC: Valid (RRSIG present)
- ICMP: Blocked (unable to validate via ICMP)
- Geo Validation: Distance-based validation successful
---
## CONTROL PLANE ANALYSIS
- Origin ASN: 132165
- BGP Prefix: 39.34.186.0/24
- Route Stability: Unstable
- RPKI State: Not verified
- IRR Consistency: Not verified
- Route Changes (30d): 0
- DNSSEC Valid: Yes
- Has CAA: No
---
## RELATIONSHIP MAPPING
- Same Network: PTCLBB-PK (Multiple relationship entries)
- Related Hostnames: None detected
- Related Organizations: PTCLBB-PK
- Certificates: None
---
## RECOMMENDATIONS
Security Actions
- Action: Monitor - No immediate blocking required
- Firewall Rule: No specific rules recommended based on current risk profile
- WAF Configuration: Not required
Intelligence Notes
1. Low Threat Posture: IP demonstrates benign characteristics consistent with residential broadband
2. No Active Threats: Zero threat indicators observed across all monitoring periods
3. Geographic Discrepancy: Investigate conflicting geolocation data (PK vs FR) for completeness
4. Neighborhood Clean: All sibling IPs in /24 subnet classified as low-risk or clean
---
## CONCLUSION
IP 39.34.186.31/32 is a low-risk residential broadband address from Pakistan Telecom infrastructure. The IP presents no immediate threat to network security and does not require defensive blocking. Continued monitoring is recommended to track any changes in threat posture or service activity.
Overall Assessment: BENIGN - No action required beyond standard monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS132165 |
| Network Name | PTCLBB-PK |
| CIDR Block | 39.32.0.0/11 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS132165 |
| Network Prefix | 39.34.186.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 13:32:31 UTC |
| Last Seen | 2026-08-27 01:01:43 UTC |
| Profile Built | 2026-08-29 06:43:52 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 39.34.186.31
Who owns the IP address 39.34.186.31?
39.34.186.31 is registered to Munir Ahmed. The address falls within the 39.32.0.0/11 network block. Registration is held at APNIC.
Where is 39.34.186.31 located?
Geolocation data places 39.34.186.31 in Marseille, SD, France. The local time zone is Europe/Paris. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 39.34.186.31 malicious or safe?
39.34.186.31 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.